US2021232682A1PendingUtilityA1
Malware protection for virtual machines
Est. expiryJan 28, 2040(~13.5 yrs left)· nominal 20-yr term from priority
Inventors:Abhay MitraVijay KarthikVivek Sanjay JainAvishek GanguliArohi KumarKushaagra GoyalChristopher Wong
G06F 11/1451G06F 11/1469G06F 2201/84G06F 11/1461G06F 2201/81G06F 11/1464G06F 11/1484G06F 2009/45587G06F 2009/45575G06F 9/45558G06F 21/566G06F 21/564G06F 9/542G06F 21/53G06F 11/0772G06F 11/076
40
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A computer-implemented method at a data management system comprises receiving a write made to a virtual machine; computing, outside of the virtual machine, a fingerprint of the write; comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog; repeating the computing and comparing; and disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A data management system, comprising:
a storage appliance configured to store a snapshot of a virtual machine; one or more processors in communication with the storage appliance, the one or more processors configured to perform operations including:
receiving a write made to the virtual machine;
computing, outside of the virtual machine, a fingerprint of the write;
comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog;
repeating the computing and comparing; and
disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
2 . The system of claim 1 , wherein the operations further include restoring the virtual machine using the snapshot stored in the storage appliance to a state before the predetermined threshold was breached.
3 . The system of claim 1 , wherein the operations further include transmitting a warning to a user of the virtual machine.
4 . The system of claim 1 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.
5 . The system of claim 1 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time.
6 . The system of claim 1 , wherein the operations are performed in a device that is not hosting the virtual machine.
7 . The system of claim 1 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.
8 . A computer-implemented method at a data management system, the method comprising:
receiving a write made to a virtual machine; computing, outside of the virtual machine, a fingerprint of the write; comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog; repeating the computing and comparing; and disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
9 . The method of claim 8 , further comprising restoring the virtual machine using a snapshot stored in a storage appliance to a state before the predetermined threshold was breached.
10 . The method of claim 8 , further comprising transmitting a warning to a user of the virtual machine.
11 . The method of claim 8 , further comprising generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.
12 . The method of claim 8 , further comprising repeatedly generating snapshots of the virtual machine over time.
13 . The method of claim 8 , wherein the method performed in a device that is not hosting the virtual machine.
14 . The method of claim 8 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.
15 . A non-transitory, machine-readable medium storing instructions which, when read by a machine, cause the machine to perform operations comprising, at least:
receiving a write made to a virtual machine; computing, outside of the virtual machine, a fingerprint of the write; comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog; repeating the computing and comparing; and disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
16 . The machine-readable medium of claim 15 , wherein the operations further include restoring the virtual machine using a snapshot stored in a storage appliance to a state before the predetermined threshold was breached.
17 . The machine-readable medium of claim 15 , wherein the operations further include transmitting a warning to a user of the virtual machine.
18 . The machine-readable medium of claim 15 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.
19 . The machine-readable medium of claim 15 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time.
20 . The machine-readable medium of claim 15 , wherein the operations are performed in a device that is not hosting the virtual machine.
21 . The machine-readable medium of claim 15 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.Join the waitlist — get patent alerts
Track US2021232682A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.